<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ThreatFire Research Blog &#187; Storm</title>
	<atom:link href="http://blog.threatfire.com/category/storm/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.threatfire.com</link>
	<description>ThreatFire™ AntiVirus protects when others can&#039;t</description>
	<lastBuildDate>Mon, 15 Mar 2010 15:00:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>More Valentine&#8217;s Day Waledac Love</title>
		<link>http://blog.threatfire.com/2009/02/more-valentines-day-waledac-love.html</link>
		<comments>http://blog.threatfire.com/2009/02/more-valentines-day-waledac-love.html#comments</comments>
		<pubDate>Fri, 13 Feb 2009 17:24:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Storm]]></category>
		<category><![CDATA[Waledac]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2009/02/more-valentines-day-waledac-love/</guid>
		<description><![CDATA[
With Valentine&#8217;s day approaching, the group continues to spam out links to a new set of sites with some new themes and filenames to watch for, like &#8220;reader.exe&#8221; and &#8220;run.exe&#8221;. The pages do not yet seem to carry redirects to pages hosting exploits. Instead, the text directs the user to &#8220;Click here to view your [...]]]></description>
			<content:encoded><![CDATA[<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_YaXoRZbsXc4/SZWtPs6UprI/AAAAAAAAAvo/9sFI8-rgZZw/s1600-h/vday_wish.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 205px;" src="http://2.bp.blogspot.com/_YaXoRZbsXc4/SZWtPs6UprI/AAAAAAAAAvo/9sFI8-rgZZw/s400/vday_wish.png" alt="" id="BLOGGER_PHOTO_ID_5302334621564053170" border="0" /></a></p>
<p>With Valentine&#8217;s day approaching, the group continues to spam out links to a new set of sites with some new themes and filenames to watch for, like &#8220;reader.exe&#8221; and &#8220;run.exe&#8221;. The pages do not yet seem to carry redirects to pages hosting exploits. Instead, the text directs the user to &#8220;Click here to view your card.&#8221; Do not download and run these executables. Instead, please click on this post&#8217;s Waledac blog label below for previous posts about the ongoing threat.</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_YaXoRZbsXc4/SZWtFo4omsI/AAAAAAAAAvg/o7enjl1AN5E/s1600-h/NewHeart.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 269px;" src="http://2.bp.blogspot.com/_YaXoRZbsXc4/SZWtFo4omsI/AAAAAAAAAvg/o7enjl1AN5E/s400/NewHeart.png" alt="" id="BLOGGER_PHOTO_ID_5302334448684538562" border="0" /></a></p>
<p>And another&#8230;</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_YaXoRZbsXc4/SZo7RCpsT3I/AAAAAAAAAvw/Lf8MpPWvhSU/s1600-h/happy.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 218px;" src="http://1.bp.blogspot.com/_YaXoRZbsXc4/SZo7RCpsT3I/AAAAAAAAAvw/Lf8MpPWvhSU/s320/happy.png" alt="" id="BLOGGER_PHOTO_ID_5303616675137736562" border="0" /></a></p>
<p>Messages related to the image above include subjects like &#8220;A Valentine E-Card from <insert name="" here="">&#8221; and text like&#8230;<br /><name> has sent you a Valentine&#8217;s Day greeting card and wrote this to you:<br />&#8220;Heaven is not heaven without U&#8221;</name></insert><br /><insert name="" here=""><name>Just click on the following link to see your E-card:<br />hxxp://yolk .fun loveonline .com/?cardnum=<rand_num><br />For your convenience, the greeting card will be available for the next 30 days.&#8221;</rand_num></name></insert><br /><insert name="" here=""><name><rand_num>Do not click on the link or download the malware at that link.</rand_num></name></insert></p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_YaXoRZbsXc4/SZr4IIms-7I/AAAAAAAAAv4/H7S14x-gZr8/s1600-h/bird.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 240px;" src="http://1.bp.blogspot.com/_YaXoRZbsXc4/SZr4IIms-7I/AAAAAAAAAv4/H7S14x-gZr8/s320/bird.png" alt="" id="BLOGGER_PHOTO_ID_5303824329814637490" border="0" /></a><br />Messages wishing you a<span style=";font-family:&quot;;font-size:11;"  ></span> &#8220;Happy Valentines Day!&#8221; contain text like</p>
<p>Flora just mailed an electronic Valentine greeting card and wrote this to you:<br />&#8220;love u so much dear..&#8221;</p>
<p>To view this page please click here:<br />hxxp:// ii. cherishpoems.com/?code=rand_num<br />You can see your card at any time within 30 days.&#8221;</p>
<p>Leading to teddy bear malware:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_YaXoRZbsXc4/SZsGqvqBNbI/AAAAAAAAAwA/aJKuimKYtiM/s1600-h/bear.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 255px;" src="http://1.bp.blogspot.com/_YaXoRZbsXc4/SZsGqvqBNbI/AAAAAAAAAwA/aJKuimKYtiM/s320/bear.png" alt="" id="BLOGGER_PHOTO_ID_5303840317575869874" border="0" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2009/02/more-valentines-day-waledac-love.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puppy Love Development Kit</title>
		<link>http://blog.threatfire.com/2009/02/puppy-love-development-kit.html</link>
		<comments>http://blog.threatfire.com/2009/02/puppy-love-development-kit.html#comments</comments>
		<pubDate>Mon, 09 Feb 2009 16:32:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Storm]]></category>
		<category><![CDATA[Waledac]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2009/02/puppy-love-development-kit/</guid>
		<description><![CDATA[
In one of their more complicated themes, the Waledac team is following up on a previous blast, spamming out links to a few new malicious websites, each one using a strange &#8220;Valentine Devkit&#8221; theme. Clicking on an image on one of these pages results in a download of various names: loveprogramm.exe, ecard.exe, postcard.exe, lovekit.exe, mylove.exe, [...]]]></description>
			<content:encoded><![CDATA[<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_YaXoRZbsXc4/SZBa8fQqEjI/AAAAAAAAAvY/5fZn0VVILSs/s1600-h/puppies.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 361px; height: 400px;" src="http://2.bp.blogspot.com/_YaXoRZbsXc4/SZBa8fQqEjI/AAAAAAAAAvY/5fZn0VVILSs/s400/puppies.png" alt="" id="BLOGGER_PHOTO_ID_5300836756645089842" border="0" /></a></p>
<p>In one of their more complicated themes, the Waledac team is <a href="http://blog.threatfire.com/2009/01/valentines-day-waledac-theme.html" target="_blank">following up on a previous blast</a>, spamming out <a href="http://www.shadowserver.org/wiki/uploads/Calendar/waledac_domains.txt" target="_blank">links</a> to a few new malicious websites, each one using a strange &#8220;Valentine Devkit&#8221; theme. Clicking on an image on one of these pages results in a download of various names: <a href="http://www.threatexpert.com/report.aspx?md5=d0c6d8e67170ab90aacb101ccbaa9c21" target="_blank">loveprogramm.exe, ecard.exe, postcard.exe, lovekit.exe, mylove.exe, runme.exe, loveexe.exe</a>&#8230; The files themselves are effectively obfuscated, with very low (non-existent) AV scanner detection at the current time. The site suggests that a &#8220;nicely designed Valentines Card for your sweetheart&#8221; can be created with their &#8220;Valentine Devkit&#8221;.</p>
<p>The web pages seem unusual for the group in one respect, they do not provide the &#8220;google-analytics.js&#8221; javascript link that was present on previous campaigns. That means the team is not delivering the commodity client side exploits (drive-by exploits) to distribute their malware just yet. Instead, they are relying on the gullibility of users to download and install the malware files on their own. ThreatFire currently is preventing the malware in our community in low volume.</p>
<p>There seem to be some legitimate development kits of this sort: on another web site, <a href="http://forums.pcworld.com/blogs;jsessionid=717F438375CBDEF3BC7F2E5D7595A747" target="_blank">instructions </a>that may be getting confused and mimicked with the Waledac gang&#8217;s devkit explain how to use another &#8220;devkit&#8221; to create a Flash ecard in time for Valentine&#8217;s Day. Other searches for Valentine&#8217;s Day Dev Kits produce kits to be run on other operating systems.</p>
<p>We&#8217;ll share some additional research notes on the malware&#8217;s functionality and its obfuscation, be sure to check in later.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2009/02/puppy-love-development-kit.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Valentine&#8217;s Day Waledac Theme</title>
		<link>http://blog.threatfire.com/2009/01/valentines-day-waledac-theme.html</link>
		<comments>http://blog.threatfire.com/2009/01/valentines-day-waledac-theme.html#comments</comments>
		<pubDate>Fri, 23 Jan 2009 11:55:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Bot]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Storm]]></category>
		<category><![CDATA[Undetected malware]]></category>
		<category><![CDATA[Waledac]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2009/01/valentines-day-waledac-theme/</guid>
		<description><![CDATA[In their most predictable fashion, the distributors of Waledac are engineering a new valentine&#8217;s day scheme for their malware delivery. The ThreatFire community is preventing you.exe, meandyou.exe, and onlyyou.exe from being run on desktops. The web servers appear to be serving the same file from each site with the names above, which ThreatExpert identifies accurately.

The [...]]]></description>
			<content:encoded><![CDATA[<p>In their most predictable fashion, the distributors of Waledac are engineering a new valentine&#8217;s day scheme for their malware delivery. The ThreatFire community is preventing you.exe, meandyou.exe, and onlyyou.exe from being run on desktops. The web servers appear to be serving the same file from each site with the names above, which ThreatExpert <a href="http://www.threatexpert.com/report.aspx?md5=35b48da0e6ccfe75443f5f727a8f400a" target="_blank">identifies accurately</a>.</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_YaXoRZbsXc4/SXmyg1RIPZI/AAAAAAAAAug/r-7r00c2-qs/s1600-h/goodnewsreview.png" target="_blank"><img id="BLOGGER_PHOTO_ID_5294459114075209106" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 200px; CURSOR: pointer; HEIGHT: 138px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_YaXoRZbsXc4/SXmyg1RIPZI/AAAAAAAAAug/r-7r00c2-qs/s200/goodnewsreview.png" border="0" /></a></p>
<p>The distributors currently are using<br />hxxp://goodnewsreview.com<br />hxxp://worldnewseye.com<br />hxxp://www.spacemynews.com<br />hxxp://www.worldnewsdot.com<br />hxxp://www.worldtracknews.com<br />hxxp://www.wapcitynews.com<br />hxxp://linkworldnews.com<br />hxxp://goodnewsdigital.com<br />hxxp://waleprojekt.com<br />hxxp://expowale.com<br />hxxp://topwale.com<span class="Apple-style-span" style="WORD-SPACING: 0px; FONT: 12px/16px arial; TEXT-TRANSFORM: none; COLOR: rgb(51,51,51); TEXT-INDENT: 0px; WHITE-SPACE: normal; LETTER-SPACING: normal; BORDER-COLLAPSE: separate; TEXT-ALIGN: left; orphans: 2; widows: 2"></span><br />to serve up some these files and the nice graphics above with a cute question &#8220;Guess, which one is for you?&#8221;. Old sites listed at Shadowserver and other sites are being re-used as well with the new valentine&#8217;s day theme. A screenshot of one of the sites is above.<br />Along with the visual pleasantries, we are also seeing the standard set of commodity exploits served up to unsuspecting visitors via a redirection to a &#8220;google-analysis.js&#8221; obfuscated javascript.</p>
<p>DO NOT VISIT THESE SITES, DO NOT DOWNLOAD AND RUN THESE EXECUTABLES.</p>
<p>Compare to last year&#8217;s Valentine&#8217;s day Storm theme that we described in a <a href="http://blog.threatfire.com/2008/01/love-in-air.html" target="_blank">post</a>, which they served up &#8220;With love!&#8221;:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_YaXoRZbsXc4/SXm5OCWFguI/AAAAAAAAAuo/Z5OBzr3Sc7A/s1600-h/storm_valentine.png" target="_blank"><img id="BLOGGER_PHOTO_ID_5294466487749542626" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 200px; CURSOR: pointer; HEIGHT: 114px; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_YaXoRZbsXc4/SXm5OCWFguI/AAAAAAAAAuo/Z5OBzr3Sc7A/s200/storm_valentine.png" border="0" /></a></p>
<p>And another of Storm&#8217;s themes that we posted about <a href="http://blog.threatfire.com/2008/01/storms-premature-invitation.html" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2009/01/valentines-day-waledac-theme.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ongoing Waledac Botnet and Spam Operation</title>
		<link>http://blog.threatfire.com/2009/01/ongoing-waledac-botnet-and-spam-operation.html</link>
		<comments>http://blog.threatfire.com/2009/01/ongoing-waledac-botnet-and-spam-operation.html#comments</comments>
		<pubDate>Wed, 07 Jan 2009 17:45:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Storm]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Waledac]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2009/01/ongoing-waledac-botnet-and-spam-operation/</guid>
		<description><![CDATA[Creating, operating and expanding the Waledac botnet is an ongoing effort, similar to the Storm operation that had dwindled this past year.
The Waledac operators have automated a fairly predictable registration and setup of their malicious web sites and corresponding online pharmaceutical sites reported as fraudulent. They are abusing fast flux dns at an impressive rate [...]]]></description>
			<content:encoded><![CDATA[<p>Creating, operating and expanding the <a href="http://blog.threatfire.com/2008/12/seasons-greetings-with-ecardexe.html" target="_blank">Waledac botnet</a> is an ongoing effort, similar to the Storm operation that had dwindled this past year.</p>
<p>The Waledac operators have automated a fairly predictable registration and setup of their malicious web sites and corresponding online pharmaceutical sites reported as fraudulent. They are abusing fast flux dns at an impressive rate as well.<br />DO NOT VISIT THESE SITES. THEY ARE MALICIOUS AND MAY INFECT YOUR SYSTEM IF YOU CHOOSE TO VISIT THEM WITH A WEB BROWSER. Here are a few that were registered and set up this morning. Be aware that this spamming/botnet operation is an ongoing one:<br />hxxp://topgreetingsite.com<br />hxxp://www.greetingsupersite.com<br />hxxp://www.greetingcardgarb.com<br />hxxp://greetingcardcalendar.com<br />hxxp://directchristmasgift.com</p>
<p>You get the idea. Do not fall for the <a href="http://blog.threatfire.com/2009/01/brought-to-you-by-123christmas.html" target="_blank">links being spammed</a> out in email messages as ecard deliveries and do not fall for the current &#8220;card.exe&#8221; being distributed.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2009/01/ongoing-waledac-botnet-and-spam-operation.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Card.exe is not Brought to you by 123Christmas-Greetings!</title>
		<link>http://blog.threatfire.com/2009/01/cardexe-is-not-brought-to-you-by-123christmas-greetings.html</link>
		<comments>http://blog.threatfire.com/2009/01/cardexe-is-not-brought-to-you-by-123christmas-greetings.html#comments</comments>
		<pubDate>Tue, 06 Jan 2009 20:31:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Adware]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Storm]]></category>
		<category><![CDATA[Waledac]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2009/01/cardexe-is-not-brought-to-you-by-123christmas-greetings/</guid>
		<description><![CDATA[Unfortunately, a handful of legitimate online greeting card sites continue to be spoofed as parts of the ongoing successful Waledac threat.While it is similar to the Storm threat, the shameless ripoff of multiple greeting card sites are even more blatent than Storm&#8217;s crafted web sites in 2007. Here is a snapshot of one of the [...]]]></description>
			<content:encoded><![CDATA[<p>Unfortunately, a handful of legitimate online greeting card sites continue to be spoofed as parts of the ongoing successful Waledac threat.<br />While it is similar to the Storm threat, the shameless ripoff of multiple greeting card sites are even more blatent than Storm&#8217;s crafted web sites in 2007. Here is a snapshot of one of the legitimate sites:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_YaXoRZbsXc4/SWPBLLCeHYI/AAAAAAAAAr4/mMMGg2rYA1E/s1600-h/123xmas.png" target="_blank"><img id="BLOGGER_PHOTO_ID_5288282785148968322" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 200px; CURSOR: pointer; HEIGHT: 132px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_YaXoRZbsXc4/SWPBLLCeHYI/AAAAAAAAAr4/mMMGg2rYA1E/s200/123xmas.png" border="0" /></a></p>
<p>And here is an example message spammed out by the Waledac worm:<br />&#8220;Jeff has mailed a e-card.<br />Just click on the following Internet address:<br />hxxp://your regards.com/ ?ID=5b830b13b073c19cabc3a06878d<br />Brought to you by 123Christmas-Greetings!&#8221;</p>
<p>Spammed message here using the Christmasbuzz name:<br />&#8220;Thomas has sent an e-card.<br />Click on the following link or copy and paste the following link into your web<br />browser&#8217;s address bar: hxxp:// smart cardgreeting.com/ ?code=844e643ab7<br />(c) Christmasbuzz.com&#8221;</p>
<p>Legitimate Christmasbuzz site looks like this snapshot:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_YaXoRZbsXc4/SWPFbNiq64I/AAAAAAAAAsI/YZS4nEmDE-E/s1600-h/xmasBuzz.png"><img id="BLOGGER_PHOTO_ID_5288287458745314178" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 200px; CURSOR: pointer; HEIGHT: 114px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_YaXoRZbsXc4/SWPFbNiq64I/AAAAAAAAAsI/YZS4nEmDE-E/s200/xmasBuzz.png" border="0" /></a></p>
<p>Another spammed message from the worm:<br />&#8220;Thomas sent you a ecard.<br />Click on the following link to see your Ecard:<br />hxxp://world greetingcard.com/ ?id=1025025ecd<br />Thanks for Using Card Fountain!&#8221;</p>
<p>And the corresponding legitimate Card Fountain web site here:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_YaXoRZbsXc4/SWPCwQ0Q0jI/AAAAAAAAAsA/V3PeKPe9skY/s1600-h/cardfountain.png" target="_blank"><img id="BLOGGER_PHOTO_ID_5288284521866777138" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 200px; CURSOR: pointer; HEIGHT: 148px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_YaXoRZbsXc4/SWPCwQ0Q0jI/AAAAAAAAAsA/V3PeKPe9skY/s200/cardfountain.png" border="0" /></a></p>
<p>Do not randomly click on links emailed to you, as pointed out <a href="http://blog.threatfire.com/2008/12/seasons-greetings-with-ecardexe.html" target="_blank">previously</a>. Ecards and greetings can be a sore spot for a lot of users before and after the holiday seasons, but it can be nice to receive holiday wishes when they come from legitimate sites.<br />Also note that most of the legitimate sites provide users with flash movies and other animated cards, instead of the &#8220;card.exe&#8221; malcode.</p>
<p>Current malicious sites are serving exploit pages and &#8220;card.exe&#8221; at the following domains, do not visit them. Some were registered by the botherders earlier today, along with a slew of domains that are now hosting online canadian pharmacy sites:<br />eternalgreetingcard.com<br />worldgreetingcard.com<br />smartcardgreeting.com<br />superyearcard.com<br />cardnewyear.com<br />newyearcardonline.com<br />youryearcard.com<br />newyearcardcompany.com<br />bestyearcard.com<br />newyearcardservice.com<br />newyearcardfree.com<br />The guys over at Shadowserver posted a writeup on the worm to close out 2008, and <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20081231" target="_blank">included a list of domains</a> being used by the botherders at the time. The distributors continue to be active.</p>
<p>And why might this Storm copycat scheme come back in vogue? Spam, of course!<br />In addition to the links to malicious attacking sites being sent out (posted in the description above), holiday-themed, seasonal spam containing links to online <a href="http://spamtrackers.eu/wiki/index.php?title=Canadian_Pharmacy" target="_blank">Canadian pharmacies</a> peddling viagra and &#8220;enhancement&#8221; drugs are being blasted by infected systems as well:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_YaXoRZbsXc4/SWPfvoEZIkI/AAAAAAAAAsQ/gqFEDVKD9ok/s1600-h/canadia_pharm.png" target="_blank"><img id="BLOGGER_PHOTO_ID_5288316396765782594" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 200px; CURSOR: pointer; HEIGHT: 92px; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_YaXoRZbsXc4/SWPfvoEZIkI/AAAAAAAAAsQ/gqFEDVKD9ok/s200/canadia_pharm.png" border="0" /></a></p>
<p>&#8220;Subject: When going on holiday take bluepills with you to ensure potence!<br />We have everything to make your love more passionate.<br />hxxp:// thank believe.com/&#8221;</p>
<p>&#8220;Be ready for spring love marathon! hxxp:// character effect.com/&#8221;</p>
<p>&#8220;Start enjoying your xxxlife! hxxp:// grew ten.com/&#8221;</p>
<p>&#8220;Subject: How intresting is your bedroom life?<br />Dont put your health at stake! hxxp:// what least.com/&#8221;</p>
<p>&#8220;Subject: Latest news from your doctor.<br />Our experts recommend! hxxp:// steam coast.com/&#8221;</p>
<p>It appears to be a fairly international spamming effort with DNS domains rapidly being registered in China and Latvia, exploit pages served in the U.S., and pharma sales coming out of Canada off of servers hosted in China.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2009/01/cardexe-is-not-brought-to-you-by-123christmas-greetings.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Season&#8217;s Greetings with a postcard.exe</title>
		<link>http://blog.threatfire.com/2008/12/seasons-greetings-with-a-postcardexe.html</link>
		<comments>http://blog.threatfire.com/2008/12/seasons-greetings-with-a-postcardexe.html#comments</comments>
		<pubDate>Tue, 30 Dec 2008 19:54:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Storm]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[cybercrime]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2008/12/seasons-greetings-with-a-postcardexe/</guid>
		<description><![CDATA[In a throwback to the Storm campaigns that we heavily reported on in 2007, another group has been spamming out links to malicious Season&#8217;s Greetings&#8217; sites (a list of domains previously serving up &#8220;ecard.exe&#8221; variants can be found here), attempting to fool users into running &#8220;postcard.exe&#8221;. Here is a screenshot of one server currently up [...]]]></description>
			<content:encoded><![CDATA[<p>In a throwback to the Storm campaigns that we heavily reported on in 2007, another group has been spamming out links to malicious Season&#8217;s Greetings&#8217; sites (a list of domains previously serving up &#8220;ecard.exe&#8221; variants can be <a href="http://isc.sans.org/diary.html?storyid=5557" target="_blank">found here</a>), attempting to fool users into running &#8220;postcard.exe&#8221;. Here is a screenshot of one server currently up this afternoon on an infected host on the Comcast network at 71.233.193.xx:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_YaXoRZbsXc4/SVp_IqP84DI/AAAAAAAAAro/VNiQOSuYPUU/s1600-h/ecard_server.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 128px;" src="http://3.bp.blogspot.com/_YaXoRZbsXc4/SVp_IqP84DI/AAAAAAAAAro/VNiQOSuYPUU/s200/ecard_server.png" alt="" id="BLOGGER_PHOTO_ID_5285676899429572658" border="0" /></a></p>
<p>A visit to this page results in multiple client side exploits, delivered by multiple redirected web pages, which TF prevents. ThreatFire also stops the attacking executable file as Trojan.Waledac.</p>
<p>The attackers make it obvious what web site they are attempting to mimic in their social engineering scheme. The entire HTML header for the attacking web page on the malicious site was ripped directly from 123greetings.com, a popular ecard site. Here is some of the header from the malicious web page:<br />Title: New Year Cards, Free New Year eCards, Greeting Cards<br />meta name =&#8221;keywords&#8221; content=&#8221;new year cards,free new year ecards,greeting cards,greetings,wishes for the new year,free e cards for new year,christmas and new year wishes,free new year greetings,free ecards for new year&#8221;<br />meta name=&#8221;description&#8221; content=&#8221;2009 is here! Fill your heart with new hopes, reach out for new opportunities and celebrate the New Year! Reach out to your friends, family,&#8230;&#8221;</p>
<p>Keep in mind that the legitimate www.123greetings.com site appears to send out ecards as Flash videos, and not as &#8220;postcard.exe&#8221; files.</p>
<p>Update (1/5/2008): Waledac variant card.exe continues to be distributed &#8212; we&#8217;re seeing hxxp://direct christmas gift.com as an offending server up and running with the same card store front.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2008/12/seasons-greetings-with-a-postcardexe.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Black Hat 2008</title>
		<link>http://blog.threatfire.com/2008/08/black-hat-2008.html</link>
		<comments>http://blog.threatfire.com/2008/08/black-hat-2008.html#comments</comments>
		<pubDate>Wed, 06 Aug 2008 22:58:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blackhat]]></category>
		<category><![CDATA[Bot]]></category>
		<category><![CDATA[Reversing]]></category>
		<category><![CDATA[Storm]]></category>
		<category><![CDATA[Virus Bulletin]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2008/08/black-hat-2008/</guid>
		<description><![CDATA[Black Hat Las Vegas 2008. If the latest Dns exploit research performed in part by Dan Kaminsky comes up in casual conversation for you, then these are your people. The ~4,500 nameless researchers and geeks at this conference rush into Ceasar&#8217;s Palace event halls to hear about recent software security research and reports.Jeff Moss kicked [...]]]></description>
			<content:encoded><![CDATA[<p>Black Hat Las Vegas 2008. If the latest Dns exploit research performed in part by Dan Kaminsky comes up in casual conversation for you, then these are your people. The ~4,500 nameless researchers and geeks at this conference rush into Ceasar&#8217;s Palace event halls to hear about recent software security research and reports.<br />Jeff Moss kicked off the con this morning with a mention that the generous BH sponsors step up to defray rising costs and not to monopolize discussion as a form of advertisement. I&#8217;m witnessing that promise realized right now, as Tom Stracener slams one of their very generous sponsors in his presentation. The knowledge is not censored here and flows freely.</p>
<p>One of the topics near and dear to our PC Tools hearts happened to be the focus of Joe Stewart&#8217;s presentation on reversing Storm titled &#8220;Protocols and Encryption of the Storm Botnet&#8221;. It was somewhat of a Virus Bulletin style presentation, but he added a lot of information regarding offensive techniques for joining the Bot network, disrupting it, and details of his findings about the bot network&#8217;s communications. It was great stuff.</p>
<p>Also interesting was Jonathan Rom&#8217;s talk on implementing a javascript based persistent rootkit. While it was somewhat stealth, I don&#8217;t know that it classified as a rootkit. However, the malcode was fairly well hidden in the plain text file he discussed. And while the design flaw that the code is dependent on for functionality has been patched in Firefox 3 and wasn&#8217;t as platform dependent as the intro suggested, the idea was well implemented against XP systems in their demo.</p>
<p>Off to another talk on the development and functionality of dns tunneling reverse shellcode.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2008/08/black-hat-2008.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lousy Storm Distribution</title>
		<link>http://blog.threatfire.com/2008/07/lousy-storm-distribution.html</link>
		<comments>http://blog.threatfire.com/2008/07/lousy-storm-distribution.html#comments</comments>
		<pubDate>Tue, 01 Jul 2008 18:53:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Storm]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2008/07/lousy-storm-distribution/</guid>
		<description><![CDATA[Our users in the Czech Republic are the first to see email spam, and download and run the newest executable from the Storm campaigns.
If you arrive at a web site with &#8220;Who is loving you? Do you want to know?&#8221;, offering up &#8220;mylove.exe&#8221;, ignore it. Don&#8217;t run the file, which immediately copies &#8220;msvecurity.exe&#8221; to the [...]]]></description>
			<content:encoded><![CDATA[<p>Our users in the Czech Republic are the first to see email spam, and download and run the newest executable from the Storm campaigns.</p>
<p>If you arrive at a web site with &#8220;Who is loving you? Do you want to know?&#8221;, offering up &#8220;mylove.exe&#8221;, ignore it. Don&#8217;t run the file, which immediately copies &#8220;msvecurity.exe&#8221; to the windows directory, and works its standard p2p magic from there.</p>
<p>Interesting to <a href="http://www.threatexpert.com/report.aspx?md5=5a59b772b94e76c36ca8b5ee7c3fb452" target="_blank">note</a> that it connects back to a chinese server on cadeaux-avenue.cn for config information.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2008/07/lousy-storm-distribution.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beijing Video</title>
		<link>http://blog.threatfire.com/2008/06/beijing-video.html</link>
		<comments>http://blog.threatfire.com/2008/06/beijing-video.html#comments</comments>
		<pubDate>Thu, 19 Jun 2008 16:24:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Bot]]></category>
		<category><![CDATA[Rootkit]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Storm]]></category>
		<category><![CDATA[Undetected malware]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2008/06/beijing-video/</guid>
		<description><![CDATA[Another round of Storm spam is now unscrupulously offering video footage of &#8220;details of this terrible disaster&#8221;, with a link to &#8220;beijing.exe&#8221;. We are seeing a low percentage of users receiving this payload so far, mostly in Dubai, falling for the message:
&#8220;A new powerful disaster just occurred in China. The most deadly, 9 magnitude, earthquake [...]]]></description>
			<content:encoded><![CDATA[<p>Another round of Storm spam is now unscrupulously offering video footage of &#8220;details of this terrible disaster&#8221;, with a link to &#8220;beijing.exe&#8221;. We are seeing a low percentage of users receiving this payload so far, mostly in Dubai, falling for the message:</p>
<p>&#8220;A new powerful disaster just occurred in China. The most deadly, 9 magnitude, earthquake took away million of lives in the heart of China, Beijing.  Rapidly growing panic paralyzed life of Chinese capital. 2008 Olympic Games are under the threat of failure. Click on the video to see the details of this terrible disaster and choose either &#8220;Open&#8221; or &#8220;Run&#8221;.&#8221;</p>
<p>Do not visit the website:</p>
<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_YaXoRZbsXc4/SFqK6VkiCTI/AAAAAAAAAY0/UEUuz-iZzF4/s1600-h/st.cn_video.png" target="_blank"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_YaXoRZbsXc4/SFqK6VkiCTI/AAAAAAAAAY0/UEUuz-iZzF4/s200/st.cn_video.png" alt="" id="BLOGGER_PHOTO_ID_5213632253462186290" border="0" /></a><br />Of course, instead of a link to a video, the code behind the &#8220;mov.gif&#8221; image of a video object directs the user to download &#8220;<a href="http://www.threatexpert.com/report.aspx?md5=3cbc68b896d9f4cfa7e84e37febf6965" target="_blank">beijing.exe</a>&#8220;, seen as &#8220;beijing[1].exe&#8221; on TF users&#8217; systems. When run, this executable drops and starts &#8220;msvupdater.exe&#8221; in the windows directory on the system. The msvupdater component carries with it the familiar P2P code that Storm uses, and attempts to send out email from the system.</p>
<p>Hidden away in the last line of html source is tiny iframe linking to &#8220;ind.php&#8221;, as seen here:<br />iframe src=&#8221;ind.php&#8221; width=&#8221;1&#8243; height=&#8221;1&#8243; style=&#8221;visibility:hidden;position:absolute&#8221;</p>
<p>This php file contains quite a bit of obfuscated javascript. After dissecting the script, we find that it is attacking an older <span style="text-decoration: underline;"></span><a href="http://www.kb.cert.org/vuls/id/292713" target="_blank">NCTAudioFile2 ActiveX vulnerability</a>, the more recent <a href="http://www.kb.cert.org/vuls/id/831457" target="_blank">RealPlayer vulnerability</a>, a older BaiduBar Soba vuln, and a couple of ancient setSlice and WebFolderView vulnerabilities. Basically, these guys have a newer commodity attack kit with some new obfuscation features.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2008/06/beijing-video.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Love is in the air</title>
		<link>http://blog.threatfire.com/2008/06/love-is-in-the-air.html</link>
		<comments>http://blog.threatfire.com/2008/06/love-is-in-the-air.html#comments</comments>
		<pubDate>Mon, 02 Jun 2008 23:11:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Bot]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Storm]]></category>

		<guid isPermaLink="false">http://newblog.threatfire.com/2008/06/love-is-in-the-air/</guid>
		<description><![CDATA[In a previous post, we opined that the Storm gang has been falling apart.
By the looks of it, they can&#8217;t even write their web pages to display properly. In the below screenshot, we have a new and currently served storm web page at top, along with the html source in the middle and a gif [...]]]></description>
			<content:encoded><![CDATA[<p>In a <a href="http://blog.threatfire.com/2008/04/storm-using-vundo-tactics.html" target="_blank">previous post</a>, we opined that the Storm gang has been falling apart.</p>
<p>By the looks of it, they can&#8217;t even write their web pages to display properly. In the below screenshot, we have a new and currently served storm web page at top, along with the html source in the middle and a gif image in another separate window that the group intended to be displayed at the top center of the original web page.</p>
<p><img id="BLOGGER_PHOTO_ID_5207433376725148642" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/_YaXoRZbsXc4/SESFEOM3I-I/AAAAAAAAAUc/DR6EjjvYVJ8/s400/whoislovingyou_mistakes.PNG" border="0" /></p>
<p>This mistake and quiet propagation, compared to the fresh and effective <a href="http://blog.threatfire.com/2007/09/whatever-happened-to-pacman.html" target="_blank">flashy pages</a> from <a href="http://blog.threatfire.com/2007/09/are-we-ready-for-some-football.html" target="_blank">almost</a> <a href="http://blog.threatfire.com/2007/10/creepy-kitty.html" target="_blank">a year ago</a>, is another sign that the Storm is calming down.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.threatfire.com/2008/06/love-is-in-the-air.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
